6 ms·
I've seen a lot of people recommend Lastpass lately, but couldn't the government force Lastpass to create a backdoor for them to get the passwords before they a
by devx 13y ago
I've seen a lot of people recommend Lastpass lately, but couldn't the government force Lastpass to create a backdoor for them to get the passwords before they are encrypted?
I'd also worry about a catastrophic event of Lastpass losing those passwords somehow, and then remaining locked out of many websites.
And what about Bittorent Sync with an old PC as an alternative? They even have an iOS app now.
- lreeves 13y agoYeah that's my concern too - any vendor can be compelled through secret courts to include backdoors in software.
- nofo_cus 13y agoI've had this worry as well, in regards to loosing passwords. I still believe writing everything down on a piece of paper can help. I have a little black journal that I carry with me everywhere that has all my passwords in it. Typing them in is the issue when they are longer strings, and mixed symbols. Only issue is protecting that journal.. Hopefully I can eat the pages if things were to arise. Ha
- w1ntermute 13y ago> Only issue is protecting that journal Or losing it.
- nofo_cus 13y agoHaha, yes or loosing it. I think that having a back up would be much needed. It's really too bad to think that we have gotten to this point. Not to be the paranoid one.
- drakeandrews 13y agoIf you are sufficiently paranoid about having to destroy the notebook, tissue paper and water soluble ink go a long way to making it easier. I made about a dozen for a murder mystery party about two years ago and still have one lying around somewhere. A small waterproof bag should make sure it isn't inadvertantly damaged in the rain.
- samatman 13y agoThe more dramatic solution is flash paper, which destroys all conceivable evidence. Don't fly with it. http://en.wikipedia.org/wiki/Nitrocellulose http://en.wikipedia.org/wiki/Nitrocellulose
- drakeandrews 13y agoI'd be very wary about carrying a book of flashpaper in my pocket.
- TheEskimo 13y agoI personally use keepass and keepassx (the alpha compatible with keepass2.x) and sync my passwords with SpiderOak. That's worked pretty well for me, and I don't actually have to trust a website with my passwords. Even if there's an insecurity in SpiderOak, they'd only get my encrypted keepass database which they'd then have to also decrypt. I definitely recommend keepass over lastpass.
- SkyMarshal 13y agoExactly what I do too, for exact same reasons. Crazy imho to store your passwords in a cloud service, using only their encryption.
- epsylon 13y ago> keepassx (the alpha compatible with keepass2.x) A bit OT, but I'm guessing you're using keepassx for non-Windows OS? Is there a benefit to it compared to simply using keepass with Mono?
- mattmaroon 13y agoIf I'm not mistaken, LastPass keeps both a local and cloud version of your password. When you're having trouble connecting to LastPass's servers, LastPass still functions. I think it's just that if the password changed on another device since the last time it synced locally, you'll still have the old one. So I'm pretty sure that you'd have to lose basically every device it's on and have LastPass's cloud deleted to lose them all.
- mchusma 13y agoThey don't keep a server version of the password (they don't have access to your password), but they do have the authentication credentials. A password manager that only worked online would be frustrating.